Bug #78889 [Asn]: php-fpm service fails to start

From: Date: Sun, 01 Dec 2019 13:07:12 +0000
Subject: Bug #78889 [Asn]: php-fpm service fails to start
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223983@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78889&edit=1 ID: 78889 Updated by: nikic@php.net Reported by: glitsj16 at riseup dot net Summary: php-fpm service fails to start Status: Assigned Type: Bug Package: FPM related Operating System: Arch Linux PHP Version: 7.4.0 Assigned To: bukka Block user comment: N Private report: N New Comment: For reference, this was added in https://github.com/php/php-src/commit/40c4d7f1820df1872a71ab07fd26da45a203e37f. Adding CAP_CHOWN sounds reasonable. What also jumps out to me is that this enables MemoryDenyWriteExecute, which seems like a very bad idea, as it should break PCRE JIT. Unless I misunderstand what this file applies to. Previous Comments: ------------------------------------------------------------------------ [2019-12-01 12:14:01] fgfgfgfg at somewhere dot com > that is, in your opinion, the administrator of the > web server, in addition to the configuration files, > must also configure the systemd-unit file itself, > if it changes something in the configuration file? surely that's what /etc/systemd/systemd/servicename.service.d/ dropins are for or in case of the distribution /usr/lib/systemd/system/servicename.service.d/ if you change or add something you are supposed to know what you are doing ------------------------------------------------------------------------ [2019-12-01 09:18:44] ilya at ilya dot pp dot ua FPM is part of PHP. systemd-unit file is shipped in the PHP tarball. They decided to add a CapabilityBoundingSet to it, but they didn’t add it completely, they forgot to add CAP_CHOWN. Why do you think this is not a PHP bug? That is, in your opinion, the administrator of the web server, in addition to the configuration files, must also configure the systemd-unit file itself, if it changes something in the configuration file? ------------------------------------------------------------------------ [2019-11-30 17:16:19] glitsj16 at riseup dot net The bug is inded triggered when using an AF_UNIX socket. That should have been caught by the downstream Arch maintainer(s) who decided to change the defaults and broke the php-fpm service. This has been rectified via the 7.4.0-2 release so I think this can be closed. Thanks for looking into this. ------------------------------------------------------------------------ [2019-11-30 16:44:25] build+php at de-korte dot org I don't want to be picking nits, but in the default configuration, php-fpm will listen to an AF_INET socket (127.0.0.1:9000), not an AF_UNIX socket (/run/php-fpm/php-fpm.sock) like mentioned in this report. The reported issue will only occur in the latter case, not in the first (which is the default). ------------------------------------------------------------------------ [2019-11-30 13:39:16] cmb@php.net Jakub, could you please check this? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78889 -- Edit this bug report at https://bugs.php.net/bug.php?id=78889&edit=1

« previous php.bugs (#223983) next »